PT-2026-83734 · Hulumi · Hulumi
CVE-2026-82857
·
Published
2026-08-31
·
Updated
2026-08-31
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
hulumi versions prior to 1.3.2
Description
A privilege escalation issue exists in the weekly integration IAM (Identity and Access Management) policy. This flaw allows role lifecycle operations on
af-e2e-* roles due to insufficient boundary restrictions. An attacker with the documented principal can exploit this to create persistent roles with higher privileges within the sandbox account.Recommendations
Update hulumi to version 1.3.2 or later.
Exploit
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hulumi